Social USB-C — Privacy Policy
Draft — not yet reviewed by a lawyer.
Last updated: 30 September 2026
Note: this Policy is published in English so that the review teams at Google, Meta and TikTok can read it. A French version will follow.
1. Who is responsible for your data
Social USB-C (the "Service") is operated by YANNIS HAISMANN OÜ, a private limited company registered in Estonia under number 17576158, with its registered office at Tartu mnt 67/1-13b, 10115 Tallinn, Estonia. We are the data controller for the personal data described in this Policy.
We are not required to appoint a Data Protection Officer and have not appointed one. For anything about your data, write to privacy@socialusbc.com.
2. In short
- Social USB-C connects the social media accounts you choose and publishes or schedules posts in your name. To do that, we store the access tokens the platforms give us, the content you upload, and basic profile and performance data from each platform.
- We use this data only to run the Service for you. We do not sell it, do not use it for advertising, and do not use it to train artificial intelligence models.
- You can disconnect any platform, or delete your whole account, at any time. Deletion instructions are at https://socialusbc.com/data-deletion.
- Access tokens are kept only while an account stays connected. Uploaded media is deleted 30 days after publication. Technical logs are deleted after 90 days.
3. Data we collect
Account data. Your email address, your name, your password (stored as a hash) or sign-in method, your plan, your language and time zone, and your preferences.
Data from the platforms you connect. When you connect a platform through its official authorisation flow (OAuth), we receive an access token, and sometimes a refresh token, that lets us act on your behalf within the permissions you approved. We also receive the identifiers and public profile information needed to show you which account is connected. Section 4 lists what we receive from each platform.
Content you upload. Videos, images, captions, titles, descriptions, hashtags, and the settings you choose for each post (destination accounts, visibility, publication time, platform-specific options).
Publishing records. For each post we publish, the platform's post identifier, its public URL, its status, and the time of publication.
Performance data. Basic figures the platforms return for the posts we published for you (views, likes, comments, shares and similar), and basic figures about the connected account when the platform exposes them (for example, subscriber or follower count).
Billing data. Your plan, invoices, and payment status. Card details are entered on Stripe's forms and processed by Stripe. We never see your full card number.
Technical data. IP address, browser and device type, pages visited in the Service, actions taken (for example "post scheduled", "account disconnected"), and error reports.
Support data. The emails you send us and our replies.
We do not collect data about people under 18. The Service is reserved for adults.
4. Data received from each platform
4.1 YouTube and Google
The Service uses YouTube API Services. By connecting a YouTube channel, you also agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's handling of your data is described in the Google Privacy Policy (https://policies.google.com/privacy).
Social USB-C's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
What we request. When you connect a YouTube channel, we ask for these Google permissions (scopes): [SCOPES PLACEHOLDER, expected: https://www.googleapis.com/auth/youtube.upload to upload videos, https://www.googleapis.com/auth/youtube.readonly to read your channel and the videos we published, and https://www.googleapis.com/auth/yt-analytics.readonly for basic statistics]. You see the exact list on Google's consent screen and you can refuse.
What we collect through YouTube API Services:
- the OAuth access token and refresh token for your Google account;
- your channel identifier, channel name, handle and channel picture;
- for the videos we upload for you: the video identifier, title, description, tags, privacy status, scheduled publication time and thumbnail;
- basic statistics for those videos and for your channel: views, likes, comments count, subscriber count.
How we use it:
- to show which channel is connected;
- to upload the videos you choose, with the title, description, visibility and schedule you set;
- to show you how those videos perform inside the Service.
We do not use YouTube data for advertising, we do not serve third-party advertisements in the Service, we do not track you across devices, and we do not sell or share YouTube data with anyone except the processors listed in section 7, who act on our instructions.
Storage and refresh. We keep the tokens for as long as your channel stays connected. We keep the other data received from YouTube for no longer than 30 calendar days without refreshing it from the API; after 30 days it is either refreshed or deleted.
Revoking access. You can disconnect YouTube from your settings in the Service, or revoke Social USB-C's access to your Google data at any time from the Google security settings page at https://security.google.com/settings/security/permissions. When you revoke access, we delete all data received from YouTube for your account within 30 calendar days. If you ask us directly at privacy@socialusbc.com to delete your YouTube data, we do it within 7 calendar days.
Human access. No one at Social USB-C reads your YouTube data unless you ask for support on a specific item, or unless we need to investigate a security incident, abuse, or a legal claim.
4.2 Facebook, Instagram and Threads (Meta)
We access Meta platforms through Facebook Login, the Instagram API and the Threads API, under the Meta Platform Terms (https://developers.facebook.com/terms/).
What we receive:
- Facebook: your app-scoped user identifier, name and profile picture, the list of Facebook Pages you manage, and, for each Page you connect, the Page identifier, name, picture and Page access token;
- Instagram: the identifier, username and profile picture of the Instagram professional account you connect, and its access token;
- Threads: the identifier, username and profile picture of the Threads account you connect, and its access token;
- for the posts we publish on these platforms: the post or media identifier, its permalink and status, and basic insights (reach, likes, comments, shares) where the platform exposes them.
How we use it: to show which accounts are connected, to publish and schedule the content you choose on those accounts, and to show you basic performance figures. We use Meta data only for these purposes, and only as described in Meta's developer documentation.
Storage: tokens are kept while the account stays connected. Profile data is refreshed when you use the Service and deleted when you disconnect. Insights are cached for 30 days.
Deletion: you can delete Meta data by disconnecting the account in the Service, by deleting your Social USB-C account, by writing to privacy@socialusbc.com, or by removing Social USB-C from your Facebook, Instagram or Threads settings. Removal from Facebook sends us an automatic deletion request. In every case, we delete the data within 30 days. We also delete Meta data when Meta asks us to, when it is no longer needed, and when the law requires. Full instructions: https://socialusbc.com/data-deletion.
4.3 TikTok
We access TikTok through TikTok Login Kit and the TikTok Content Posting API, under the TikTok Developer Terms of Service.
What we receive: your TikTok open identifier and union identifier, display name and avatar; the creator settings that TikTok returns before a post (the privacy levels available, whether comments, duets and stitches are allowed, the maximum video duration); the status of each post we publish; and, if you grant the corresponding permission, the identifiers and basic statistics of the videos we published. [SCOPES PLACEHOLDER, expected: user.info.basic, video.publish, video.upload, video.list]
How we use it: to show which TikTok account is connected, to display your name and avatar before each post as TikTok requires, to publish the videos and photos you choose with the title, privacy level, interaction settings and commercial content disclosure you select, and to show you basic performance figures. Nothing is sent to TikTok until you have previewed the post and confirmed it.
Storage and deletion: tokens are kept while the account stays connected. Creator settings are fetched at the time of each post and not kept beyond 30 days. You can delete TikTok data by disconnecting in the Service, by deleting your account, by writing to privacy@socialusbc.com, or by removing Social USB-C in TikTok under Settings and privacy, then Security and permissions, then Manage app permissions. We delete the data within 30 days.
4.4 LinkedIn, X, Pinterest, Bluesky and Mastodon
For each of these platforms we receive an access token, the identifier of your account (and, for LinkedIn, of the organisation pages you choose to connect), your public display name, handle and picture, and the identifiers and basic statistics of the posts we publish. For Mastodon we also store the address of the server that hosts your account. We use this data for the same purposes as above: showing which account is connected, publishing what you choose, and showing basic performance. The same storage and deletion rules apply.
5. Why we use your data, and on what legal basis
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:
- To provide the Service you signed up for (article 6(1)(b), performance of a contract): creating and managing your account, connecting platforms, storing and publishing your content, scheduling, showing analytics, billing, and answering support requests.
- To comply with the law (article 6(1)(c)): keeping invoices and accounting records, answering lawful requests from authorities, handling your data protection rights.
- For our legitimate interests (article 6(1)(f)): keeping the Service secure, preventing abuse and fraud, fixing errors, measuring how the Service is used in aggregate, and sending you service messages about your account. We have checked that these interests do not override your rights, and you can object at any time.
- With your consent (article 6(1)(a)): optional analytics cookies, and marketing emails if you opt in. You can withdraw consent at any time without affecting what happened before.
We do not make automated decisions that have legal or similarly significant effects on you.
6. Who we share data with
We do not sell personal data. We share it only with:
- The platforms you connect. When you publish, we send your content and settings to the platform. Each platform then processes it under its own terms and privacy policy, as an independent controller.
- Our processors, listed in section 7, who handle data on our instructions under a data processing agreement.
- Authorities or courts when the law requires it, and advisers (lawyers, accountants) bound by confidentiality, when needed to defend our rights.
- A successor if our business is sold or merged, with notice to you, and with the same protections.
We do not share platform data with other apps, and we do not share it with data brokers, advertisers or AI model providers.
7. Our processors
- Vercel Inc. (USA): hosting of the application and its serverless functions. [REGION PLACEHOLDER: state the deployment region, for example Frankfurt, if EU-only hosting is chosen]
- [DATABASE PROVIDER PLACEHOLDER] (region: [PLACEHOLDER]): Postgres database that stores account data, tokens (encrypted), post records and analytics.
- [MEDIA STORAGE PROVIDER PLACEHOLDER] (region: [PLACEHOLDER]): storage of uploaded videos and images until they are published and deleted.
- Stripe Payments Europe Ltd (Ireland) and Stripe Inc. (USA): payment processing and invoicing.
- Google Ireland Ltd (Google Workspace): our email and document tools, used for support correspondence.
- [EMAIL DELIVERY PROVIDER PLACEHOLDER]: sending account and service emails.
- [ANALYTICS PROVIDER PLACEHOLDER, for example PostHog]: usage analytics, only with your consent for non-essential tracking.
- [ERROR MONITORING PROVIDER PLACEHOLDER]: error reports, which may contain your account identifier and the action that failed.
We keep this list up to date on this page.
8. Transfers outside the European Union
Some of our processors are based in, or have operations in, the United States. When personal data leaves the European Economic Area, we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework for providers certified under it, and otherwise on the Standard Contractual Clauses approved by the European Commission, with additional safeguards where needed. You can ask privacy@socialusbc.com for a copy of the relevant safeguards.
The platforms themselves (Google, Meta, TikTok, LinkedIn, X, Pinterest, Bluesky, Mastodon servers) receive your content because you asked us to publish there. Their own transfer rules apply.
9. Data retention
We keep data only as long as needed for the purpose it was collected for. Concretely:
- Account data: for as long as your account exists, then deleted within 30 days after you delete your account or ask us to.
- OAuth access and refresh tokens: for as long as the platform account stays connected. Deleted immediately when you disconnect in the Service, and within 30 days when you revoke access on the platform side.
- Profile data received from platforms (identifiers, names, pictures, page lists): while the account stays connected, refreshed when you use the Service. Data received from YouTube is refreshed or deleted within 30 calendar days.
- Uploaded media (videos, images): deleted 30 days after the post has been published on every platform you selected, or 30 days after the scheduled date if publishing failed. Drafts you keep are stored until you delete them or your account.
- Publishing records (post identifiers, URLs, status): for as long as your account exists.
- Cached performance data: 30 days on a rolling basis, then refreshed or deleted.
- Technical logs and error reports: 90 days, then deleted automatically.
- Billing records and invoices: 7 years after the end of the financial year, as required by Estonian accounting law.
- Support emails: 2 years after the last exchange.
- Records of deletion requests (email, date, confirmation code): 12 months, to prove that we handled them.
- Backups: encrypted, overwritten within 30 days, so any deleted data can survive in a backup for at most 30 days.
10. Your rights
Under the GDPR you can:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data (see https://socialusbc.com/data-deletion for the fastest route);
- restrict how we use your data while a dispute is examined;
- receive the data you gave us in a machine-readable format, and have it sent to another provider where technically feasible;
- object to processing based on our legitimate interests, and to any marketing at any time;
- withdraw consent where processing is based on consent.
To exercise these rights, write to privacy@socialusbc.com. We answer within one month; for complex requests we may extend by up to two months and will tell you why. We may ask you to confirm your identity.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, https://www.aki.ee, info@aki.ee). You may also contact the authority of the country where you live, for example the CNIL in France (https://www.cnil.fr).
11. Cookies and similar technologies
The Service uses:
- Essential cookies, which are needed to keep you signed in, protect forms against forgery, and remember your cookie choice. These do not require consent. [COOKIE NAMES PLACEHOLDER]
- Analytics cookies or identifiers, only if you accept them in the cookie banner, to understand how the Service is used and improve it. [ANALYTICS TOOL PLACEHOLDER]
We do not use advertising cookies, and we do not allow third parties to place advertising trackers in the Service. You can change your choice at any time from the "Cookies" link in the footer, and you can delete cookies from your browser settings.
12. Security
We protect your data with encryption in transit (TLS), encryption of platform tokens at rest, access limited to the people who need it, separate environments for development and production, and monitoring of unusual activity. No system is perfectly secure. If a breach affects your data and creates a risk for you, we will tell you and the supervisory authority as the law requires.
13. Children
The Service is reserved for people aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, write to privacy@socialusbc.com and we will delete it.
14. Changes to this Policy
We may update this Policy when the Service, our processors or the law change. For material changes we will email you or show a notice in the Service before they take effect. The date at the top tells you when it was last changed. Earlier versions are available on request.
15. Contact
YANNIS HAISMANN OÜ, Tartu mnt 67/1-13b, 10115 Tallinn, Estonia, Estonia. Registration number 17576158.
- Privacy and data rights: privacy@socialusbc.com
- Support: support@socialusbc.com
- Legal: legal@socialusbc.com